Hide Forgot
Description of problem: The permissions are too restrictive on /var/run/opendmarc, only the opendmarc user and nobody else can read sockets in this directory: [root@gatekeeper opendmarc]# ls -al /run/opendmarc/ total 0 drwx------. 2 opendmarc opendmarc 40 Oct 13 17:18 . drwxr-xr-x. 37 root root 1020 Oct 13 17:19 .. [root@gatekeeper opendmarc]# rpm -q -f /run/opendmarc/ opendmarc-1.3.2-1.el8.x86_64 Version-Release number of selected component (if applicable): opendmarc-1.3.2-1.el8.x86_64 How reproducible: Always Steps to Reproduce: 1. Install opendmarc on epel8. 2. 3. Actual results: /var/run/opendmarc/ inaccessible. Expected results: /var/run/opendmarc/ accessible to members of opendmarc group. Additional info:
Just hit this again, we have a DoS on every update. Any news?
Hit this again, any news? PRs submitted to fix this; https://src.fedoraproject.org/rpms/opendmarc/pull-request/7 https://src.fedoraproject.org/rpms/opendmarc/pull-request/6 https://src.fedoraproject.org/rpms/opendmarc/pull-request/5 https://src.fedoraproject.org/rpms/opendmarc/pull-request/4 https://src.fedoraproject.org/rpms/opendmarc/pull-request/3 https://src.fedoraproject.org/rpms/opendmarc/pull-request/2
Hi Graham, unfortunately i do not have time to maintain Opendmarc. The package is now orphaned. If you are a maintainer then please consider taking it. Apologies.
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
I am not a maintainer but am happy to become one - are you in a position to hold my hand through the process or pass me on to someone who is?
Hey Graham. I just took this package because I use it... I'd be very happy to have someone else work on it. :) Can you look at doing a pull request for it for rawhide? (You will need to use https to push/pull your fork on src.fedoraproject.org until you are a packager, see https://fedoraproject.org/wiki/Infrastructure/HTTPS-commits ) There's a number of issues outstanding. This issue, the version to fix some cve's, etc. Feel free to drop me email or ask me here if you have any questions on process, etc. If we can get things working well in rawhide, I can add you to packagers and you can update the other branches? Sound reasonable?
This specific PR is the rawhide patch: https://src.fedoraproject.org/rpms/opendmarc/pull-request/2 Am I understanding correctly that we apply to rawhide first, and if people are happy, backport as appropriate?
So, I ended up changing a bunch of things in the packaging here and moving to 1.4.0 upstream (they are becoming more active again on gihutb now). Can I get folks to test? rawhide/f35: http://koji.fedoraproject.org/koji/taskinfo?taskID=66668437 f34: http://koji.fedoraproject.org/koji/taskinfo?taskID=66668626 f33: http://koji.fedoraproject.org/koji/taskinfo?taskID=66668868 f32: http://koji.fedoraproject.org/koji/taskinfo?taskID=66668906 epel8: http://koji.fedoraproject.org/koji/taskinfo?taskID=66668617 epel7: http://koji.fedoraproject.org/koji/taskinfo?taskID=66669466 I'll probibly push this to rawhide later today and see about pushing other releases based on feedback. Graham: I am going to close your PR's... I took that into the changes I made, so I'll close the ones on the interface. Many thanks tho... If you are still interested in co-maintaining happy to arrange that... these 1.4.0 changes were kind of difficult. Perhaps upstream will be better moving forward now that they are moving to github, etc.
FEDORA-2021-c1b846164e has been submitted as an update to Fedora 34. https://bodhi.fedoraproject.org/updates/FEDORA-2021-c1b846164e
FEDORA-2021-c1b846164e has been pushed to the Fedora 34 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2021-c1b846164e` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2021-c1b846164e See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2021-c1b846164e has been pushed to the Fedora 34 stable repository. If problem still persists, please make note of it in this bug report.